Atomicorp WAF Research Notes
Research Update - 2026-09-16
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2026-0768 | Langflow <=1.2.x - Unauthenticated Remote Code Execution via validate_code | 340095 |
| CVE-2026-61560 | @zereight/mcp-gitlab's unauthenticated arbitrary file read via upload_markdown enables PAT exfiltration and full accou | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-62379 | OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-61559 | @zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-61568 | @zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport | 390719 |
| CVE-2023-54398 | Yonyou U8 Cloud Java Deserialization RCE via FileManageServlet | 340014 , 340023 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390614 |
| CVE-2024-58385 | Yonyou U8 CRM SQL Injection via fillbacksettingedit.php | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-89026 | Issabel Framework Hard-coded JWT Key RCE via pbxapi/manager/originate | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 |
| CVE-2026-89308 | Arbitrary command execution in TrxTimeATTENDANCE | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-91931 | Flowise before 3.1.4 Remote Code Execution via Custom MCP npx | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-52484 | MitraStar GPT-2742GX4X5v6-SV GL_g2.5_100XNT0b23_3 Arbitrary Code Execution Vulnerability | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655 |
| CVE-2026-91935 | Flowise before 3.1.4 SSRF and API Key Exfiltration via Chat Model Nodes | 310047 , 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-91940 | crawl4ai before 0.9.3 Arbitrary File Write via PDFContentScrapingStrategy | 340007 , 344360 , 390709 |
| CVE-2026-91989 | atomic-agents-stack before 1.1.0 Path Traversal via dashboard serve.py | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-44203 | OpenAM: Pre-auth Reflected XSS in OAuth2 / OIDC response_mode=form_post via state parameter (FormPostResponse.ftl) | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-54549 | Meta Ads MCP: Server-Side Request Forgery (SSRF) in upload_ad_image via Unrestricted image_url Fetch | 334168 , 390719 |
| CVE-2026-91943 | Crawl4AI before 0.9.3 SSRF via PDFContentScrapingStrategy | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-79425 | CRMEB v6.0.0 Server-Side Request Forgery Vulnerability | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-55864 | GeoNetwork: Unauthenticaded Server-Side Request Forgery in SLD Tool | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-76820 | OpenCTI: Synchronizer SSRF: stream fetch has no URL validation | 337109 , 337110 , 344360 , 390719 , 398021 , 398022 |
| CVE-2026-54544 | Fireshare has unauthenticated SSRF via missing login_required on webhook test endpoints | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-54077 | ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated users | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-58485 | mcp-searxng: DNS-resolved Private Hostname SSRF in web_url_read | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-58502 | githubtoplanguages: Command Injection via Issue Title in Discord Notification Workflow | 340014 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-91966 | AVideo through 29.0 Unauthenticated SSRF via Host Header | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-54688 | mcp-searxng: SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off) | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-88618 | 1024-lab SmartAdmin v3.30.0 Arbitrary Code Execution Vulnerability | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-62280 | OpenAM Reflected XSS in the OAuth2/OIDC wap consent page | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-55591 | Signal K Server: Server-Side Request Forgery via Remote Connection Endpoints | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-91848 | WuzhiCMS index.php getDataOfJson sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-32599 | Netmaker has a boolean‑based SQL Injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-44202 | OpenAM Authenticated Server-Side Request Forgery (SSRF) via /sessionservice | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-91922 | Steedos Platform through 3.0.15-beta.47 Reflected XSS via page render | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-91967 | AVideo through 29.0 Blind SSRF via getHeaderContentTypeFromURL | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-92184 | ag-ui-protocol ag-ui Multimodal Content utils.py urllib.request.urlopen server-side request forgery | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-91944 | crawl4ai before 0.9.3 DOM-based XSS via Playground UI | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-55374 | canto-saas-api: Authenticated API requests can be redirected via unencoded path variables | 340162 , 340163 , 340165 , 344365 |
| CVE-2025-10012 | Portabilis i-Educar educar_historico_escolar_lst.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-9236 | Portabilis i-Educar Tipos de usuàrio educar_tipo_usuario_lst.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-9531 | Portabilis i-Educar Agenda agenda.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-9606 | Portabilis i-Educar agenda_preferencias.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-91849 | WuzhiCMS Avatar Upload index.php setAvatar unrestricted upload | 351000 |
| CVE-2026-91853 | TOTOLINK X5000R Export Ovpn cstecgi.cgi exportOvpn os command injection | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655 |
| CVE-2026-91854 | code-projects Record Management System reg.php cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |